
ISO/IEC 27001 Certification
ISO 27001 Consulting
We guide your organisation through the full ISO/IEC 27001 certification path — pragmatic, audit-ready, and with a clear fixed-price entry point.
Why ISO 27001 Is More Than a Certificate in 2026
ISO/IEC 27001 is the international standard for Information Security Management Systems (ISMS). It does not prescribe which specific security controls an organisation must implement — instead, it defines how an organisation systematically plans, implements, monitors, and improves information security. This risk-based flexibility is what makes the standard so versatile — and also demanding, because it requires genuine engagement with your business processes.
In 2026, the certificate has become de-facto mandatory in many B2B tenders. Customers in financial services, manufacturing, and the public sector require it as evidence in supplier audits. At the same time, ISO 27001 addresses a substantial portion of the requirements arising from NIS2, DORA, and the EU AI Act — one governance framework, multiple compliance outcomes.
The economic value, however, lies in the process behind the audit stamp. Organisations that implement ISO 27001 seriously detect risks earlier, respond to incidents more systematically, and can demonstrate that security is part of their day-to-day operations rather than a one-off project.
Our Approach: From Kick-off to Certification in 9–18 Months
We start with a structured gap analysis against the Annex A controls of ISO 27001:2022. The output is a prioritised implementation roadmap calibrated to the actual maturity of your organisation, with realistic effort estimates for the open items — not a generic checklist, but a defensible plan.
Next, we define the ISMS scope together. This decision has a significant impact on project effort and on the eventual audit cost. We help you choose a scope that is regulatorily sound and operationally implementable within your existing structures. We then run risk assessment and risk treatment, and produce the Statement of Applicability (SoA) — the audit-critical core artefact of your ISMS.
During implementation, we support the development of policies, procedures, and operational evidence. We train key roles, run internal audits, and prepare your team for the external certification audit. During the audit itself, we act as your subject-matter sparring partner and help you address any corrective actions quickly and in an audit-compliant way.
ISO 27001:2022 — What Changed Compared to the 2013 Version
The 2022 revision fundamentally restructured the Annex A controls: 114 controls in 14 categories were consolidated into 93 controls across four themes (Organisational, People, Physical, Technological). Eleven new controls were introduced covering topics including threat intelligence, cloud security, ICT readiness for business continuity, data masking, and secure coding.
Organisations still holding a certification under the 2013 version face a transition deadline at the end of October 2026. Anyone certifying or recertifying now should go directly to the 2022 standard — this avoids duplicate work. We map the old controls to the new structure systematically and identify the concrete gaps to the 2022 requirements.
The new controls are particularly relevant for organisations that use cloud services, run their own software development, or rely on critical third-party providers. For each control we evaluate what evidence is appropriate in your context — and which controls can be marked "not applicable" with a defensible justification.
Common Pitfalls — and How We Avoid Them
The most common reason for failed certifications is a poorly chosen ISMS scope. Too broad creates disproportionate effort; too narrow gets pushed back by the auditor as trivial or undermines the marketing value of the certificate. We help you find a scope that is both auditable and economically implementable.
The second typical mistake is producing volumes of documentation that no one in the organisation actually uses. A thick policy manual that nobody reads does not protect — it only creates liability. We build documentation that remains usable in day-to-day work: short policies, clear ownership, procedures embedded in existing tools (Jira, Confluence, SharePoint) rather than locked in PDFs.
Third, many organisations underestimate the coordination effort: ISO 27001 is not an IT project — it is an organisation-wide governance initiative. It requires inputs from IT, HR, Legal, Procurement, and executive management. We act as the external programme manager and shoulder this coordination burden — you provide the subject-matter input, we build the system.
What We Deliver
- Gap analysis against ISO 27001:2022 Annex A
- ISMS scope definition & risk analysis
- Statement of Applicability (SoA)
- Risk treatment plan
- Liveable policies & procedures
- Key-role training & awareness
- Internal audit & certification support
- Transition from ISO 27001:2013 to 2022
Frameworks Covered
- ISO/IEC 27001:2022
- ISO/IEC 27002:2022
- NIS2 Directive
- DORA
- EU AI Act
- BSI IT-Grundschutz
Deep dive
ISO 27001 Certification Costs
Transparent breakdown of effort and fees for SMEs and mid-market — including audit costs, internal effort, and realistic timeline.
See cost breakdownRelated
ISO 27001 for Small Business
Pragmatic certification path for organisations with 10–100 staff — without enterprise overhead.
ISMS Consulting
General ISMS implementation, with the choice between ISO 27001 and BSI IT-Grundschutz.
External Information Security Officer
After certification: ongoing ISMS operation through an external ISB.
Discuss your ISO 27001 project
We will outline a realistic approach for your organisation's size and starting point.
Get in touchFrequently Asked Questions
How long does an initial ISO 27001 certification take?
Realistically between 9 and 18 months from project kick-off. A mature organisation with existing security documentation can finish in 9 months; a greenfield ISMS in a 100-person organisation tends to require 12 to 18 months. Accelerators: clear management commitment, available internal capacity, a tightly scoped ISMS. Decelerators: parallel major projects, unclear ownership, underestimating the coordination effort. We agree a realistic timeline with you from day one.
How much does ISO 27001 certification typically cost?
Total cost breaks into three buckets: external consulting, internal personnel, and certification audit fees. For an SME with 30–80 employees, external consulting effort typically falls between €25,000 and €60,000 over the project; certification body fees for the initial audit (Stage 1 + Stage 2) usually range from €8,000 to €20,000. The largest — and most frequently underestimated — line item is internal personnel effort. A detailed breakdown is available on our ISO 27001 costs page.
Does ISO 27001 cover NIS2 and DORA?
ISO 27001 covers a substantial part of NIS2 Article 21 measures and the DORA ICT risk management framework — but not 1:1 completely. NIS2 additionally requires specific reporting obligations (24-hour early warning, 72-hour report) that a pure ISO ISMS does not explicitly model. DORA requires specific obligations on the third-party register and digital operational resilience testing that go beyond the ISO standard approach. We build the ISMS so that ISO 27001 forms the foundation and NIS2/DORA bolt on cleanly as additional modules — without duplicating documentation.
Do we need an existing security function before engaging?
No. Many of our clients start without a dedicated security organisation — they have an IT department with operational duties but no Information Security Officer. We build the security organisation jointly with you, define the necessary roles, and can take on the Information Security Officer role externally if useful. What we need on your side: an ISMS sponsor at executive level and a primary subject-matter contact who carries the project operationally.
What happens after initial certification?
The ISO 27001 certificate is valid for three years. During that period, annual surveillance audits are mandatory; a full recertification audit is due at the end of year three. Operationally that means: keep risk assessments current, document incidents, run internal audits, track corrective actions. We offer ISMS maintenance as a retainer or via our external Information Security Officer service. For organisations building up internal competence, we also support a hand-over model with progressive transfer of responsibility.
Kontakt aufnehmen
ISO 27001 Consulting for Your Organisation
From initial gap analysis to certification audit — we guide you through every step with a pragmatic, outcome-focused approach.